Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 06-01-2015 Ran by Boss at 2015-01-07 11:39:05 Run:1 Running from C:\FRST\FRST-OlderVersion Loaded Profile: Boss (Available profiles: Boss) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: CreateRestorePoint: GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com URLSearchHook: HKU\S-1-5-21-1143488406-1009695696-969558362-1000 - (No Name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.79\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.149\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File CustomCLSID: HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\Boss\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF HKU\S-1-5-21-1143488406-1009695696-969558362-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Boss\AppData\Roaming\IDM\idmmzcc5 Task: {672B2C66-A9CC-4FC4-B739-2A450415F342} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-12-26] (Google Inc.) Task: {B92E3399-CF9D-40E4-8556-1414A45F39CD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-12-26] (Google Inc.) HKU\S-1-5-21-1143488406-1009695696-969558362-1000\...\Run: [vmreg] => C:\Users\Boss\AppData\Roaming\vmreg.exe HKU\S-1-5-21-1143488406-1009695696-969558362-1000\...\RunOnce: [Adobe Speed Launcher] => 1419758942 BootExecute: autocheck autochk /p \??\E:autocheck autochk * C:\ProgramData\cmjhlmenjbmblfpekalbojkahmacgejo C:\ProgramData\iooaaifkhejokedmcodjllohnlomfnlf C:\ProgramData\InstallMate C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer GameZone C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager C:\Program Files\Mozilla Firefox\extensions C:\Program Files\Mozilla Firefox\plugins C:\Users\Boss\AppData\Local\Google\Chrome C:\Users\Boss\AppData\Roaming\appdataFr2.bin C:\Users\Boss\AppData\Roaming\ProgSense C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager C:\Users\Boss\Documents\YTD Video Downloader.lnk C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension Reg: reg delete HKCU\Software\Google\Chrome /f Reg: reg delete HKLM\SOFTWARE\Google\Chrome /f Reg: reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f Reg: reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f Reg: reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f CMD: netsh advfirewall reset EmptyTemp: ***************** Processes closed successfully. Restore point was successfully created. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully. HKU\S-1-5-21-1143488406-1009695696-969558362-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{88c7f2aa-f93f-432c-8f0e-b7d85967a527} => value deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{91EFB276-CEFE-48EC-BB3A-57795A7B4008}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}" => Key deleted successfully. "HKU\S-1-5-21-1143488406-1009695696-969558362-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}" => Key deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. HKU\S-1-5-21-1143488406-1009695696-969558362-1000\Software\Mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com => value deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{672B2C66-A9CC-4FC4-B739-2A450415F342}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{672B2C66-A9CC-4FC4-B739-2A450415F342}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B92E3399-CF9D-40E4-8556-1414A45F39CD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B92E3399-CF9D-40E4-8556-1414A45F39CD}" => Key deleted successfully. C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully. HKU\S-1-5-21-1143488406-1009695696-969558362-1000\Software\Microsoft\Windows\CurrentVersion\Run\\vmreg => value deleted successfully. HKU\S-1-5-21-1143488406-1009695696-969558362-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Adobe Speed Launcher => value deleted successfully. HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully. C:\ProgramData\cmjhlmenjbmblfpekalbojkahmacgejo => Moved successfully. C:\ProgramData\iooaaifkhejokedmcodjllohnlomfnlf => Moved successfully. C:\ProgramData\InstallMate => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer GameZone => Moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager => Moved successfully. C:\Program Files\Mozilla Firefox\extensions => Moved successfully. C:\Program Files\Mozilla Firefox\plugins => Moved successfully. C:\Users\Boss\AppData\Local\Google\Chrome => Moved successfully. C:\Users\Boss\AppData\Roaming\appdataFr2.bin => Moved successfully. C:\Users\Boss\AppData\Roaming\ProgSense => Moved successfully. C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager => Moved successfully. C:\Users\Boss\Documents\YTD Video Downloader.lnk => Moved successfully. C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. ========= reg delete HKCU\Software\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKLM\SOFTWARE\Google\Chrome /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\mountpoints2 /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= reg delete "HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes" /f ========= Operacja ukoäczona pomy˜lnie. ========= End of Reg: ========= ========= netsh advfirewall reset ========= Ok. ========= End of CMD: ========= EmptyTemp: => Removed 1.7 GB temporary data. The system needed a reboot. ==== End of Fixlog 11:45:13 ====